[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-191416-105":53,"doc-detail-191416-en":127},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":120,"head_meta":122,"extra_data":124,"updated_unix":126},105,"en","the-cyber-resilience-act-and-open-source-software-a-fine-balancing-act","The Cyber Resilience Act and Open-Source Software - A Fine Balancing Act","","This document delves into the complex relationship between the Cyber Resilience Act (CRA) and open-source software (OSS), exploring the delicate balance required to foster innovation while ensuring security. It clarifies what constitutes commercial activity when supplying OSS, providing specific indicators such as an intention to monetize beyond cost recovery, charging for the product or technical support, processing personal data as a condition of use, or accepting donations that exceed development and maintenance costs without profit intent. Conversely, it outlines activities considered outside the scope of commercial activity, including monetization solely for cost recuperation, supplying software for integration by other manufacturers without monetizing the original software, receiving financial or developmental support from manufacturers, regular releases, or contributions by non-profit organizations for non-profit objectives. The document also addresses the special regulatory regime for open-source software stewards, defined as legal entities providing sustained support for OSS development and playing a key role in its viability. This nuanced approach aims to prevent unintended burdens on the open-source community while upholding the cybersecurity objectives of the CRA.",{"@graph":63,"@context":119},[64,80,102],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/the-cyber-resilience-act-and-open-source-software-a-fine-balancing-act/191416/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/the-cyber-resilience-act-and-open-source-software-a-fine-balancing-act/191416.png","ImageObject",442,249,{"name":88,"@type":89},"Mason","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/pdf","2026-10-04","2026-09-03",true,{"@type":98,"interactionType":99,"userInteractionCount":101},"InteractionCounter",{"@type":100},"ViewAction",8,{"@type":103,"mainEntity":104},"FAQPage",[105,111,115],{"name":106,"@type":107,"acceptedAnswer":108},"What factors indicate that supplying open-source software is considered a commercial activity under the Cyber Resilience Act?","Question",{"text":109,"@type":110},"Supplying open-source software is considered a commercial activity if there's an intention to monetize beyond cost recovery, a price is charged for the product or technical support, personal data processing is a condition for use (with exceptions), or donations exceed costs without profit intent.","Answer",{"name":112,"@type":107,"acceptedAnswer":113},"What are examples of supplying open-source software that are *not* considered commercial activities?",{"text":114,"@type":110},"Activities not considered commercial include monetizing only to recuperate maintenance costs, supplying software for integration by others without monetizing the original, receiving financial or developmental support, regular releases, development by non-profits for non-profit goals, contributing to OSS without project leadership, or mere distribution on repositories.",{"name":116,"@type":107,"acceptedAnswer":117},"Who are considered open-source software stewards under the special regulatory regime?",{"text":118,"@type":110},"Open-source software stewards are legal persons who provide sustained support for the development of open-source software and play a main role in ensuring its viability.","https://schema.org",{"og:url":78,"og:type":121,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":123,"canonical":78},"index,follow",{"doc_id":125,"site_id":56},191416,1788408487,{"code":4,"msg":5,"data":128},{"doc_id":125,"user_id":129,"nickname":88,"user_avatar":130,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":131,"file_id":132,"file_url":133,"file_type":134,"file_size":135,"view_count":101,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":25,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":126,"read_time":47},5909887256941,"https://ap-avatar.wpscdn.com/davatar_9964176cb1d06d4a9deccf72a44ae3dc","| Indicative of a supplying the software in the course of a commercial activity | • An intention to monetise beyond the recuperation of actual costs\u003Cbr>• Charging a price for the product\u003Cbr>• Charging a price for technical support\u003Cbr>• Personal data processing as a condition for use of the software (except for certain justified purposes)\u003Cbr>• Accepting donations exceeding the costs of developing and maintaining the software, without the intention to make a profit. |\n| --- | --- |\n| Indicative of a supplying the software outside the course of a commercial activity | • Monetisation only to recuperate costs of maintenance, instead of making a profit (e.g., by public administration entities)\u003Cbr>• Supply of software intended to be integrated by other manufacturers, without monetisation of original software\u003Cbr>• Products which receive financial support or developmental support from manufacturers\u003Cbr>• The mere presence of regular releases\u003Cbr>• Development by non-profit organisations, if they use their earnings after cost for non-profit objectives\u003Cbr>• Contributions to open-source software when not involved in project leadership/ownership\u003Cbr>• Mere distribution on repositories |\n| Special regulatory regime | Open-source software stewards, legal persons who “provide support on a sustained basis” for the development of open-source software and play a “main role in ensuring the viability” of open-source software |","cbCaieyM78nasDVk","https://ap.wps.com/l/cbCaieyM78nasDVk","pdf",587695,"English","# Indicative of a supplying the software in the course of a commercial activity\n## Indicative of a supplying the software outside the course of a commercial activity\n# Special regulatory regime","[{\"question\":\"What factors indicate that supplying open-source software is considered a commercial activity under the Cyber Resilience Act?\",\"answer\":\"Supplying open-source software is considered a commercial activity if there's an intention to monetize beyond cost recovery, a price is charged for the product or technical support, personal data processing is a condition for use (with exceptions), or donations exceed costs without profit intent.\"},{\"question\":\"What are examples of supplying open-source software that are *not* considered commercial activities?\",\"answer\":\"Activities not considered commercial include monetizing only to recuperate maintenance costs, supplying software for integration by others without monetizing the original, receiving financial or developmental support, regular releases, development by non-profits for non-profit goals, contributing to OSS without project leadership, or mere distribution on repositories.\"},{\"question\":\"Who are considered open-source software stewards under the special regulatory regime?\",\"answer\":\"Open-source software stewards are legal persons who provide sustained support for the development of open-source software and play a main role in ensuring its viability.\"}]","The Cyber Resilience Act and Open-Source Software - A Fine Balancing Act | PDF"]